CCSP Legal, Risk, and Compliance Practice Question
A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The legal team must ensure the policy addresses key contractual and regulatory considerations. Which TWO elements should the policy include? (Choose two.)
⚠ Common exam trap
The trap here is focusing only on deletion at contract end and forgetting the need for a process to delete specific data during the contract, or accepting provider-friendly clauses that allow indefinite retention for business purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A process for the customer to request early deletion of specific data during the contract term and for the provider to confirm deletion
A robust data retention and deletion policy must include a contractual commitment for the provider to delete all customer data, including backups, after termination and to certify destruction. It should also define a process for early deletion during the contract term. These elements ensure the customer can meet regulatory retention limits and respond to data subject requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A provision allowing the provider to retain customer data indefinitely for its own business purposes
Why it's wrong here
Indefinite retention for the provider's own purposes conflicts with data minimization and retention principles under regulations like GDPR and HIPAA. It also undermines the customer's ability to comply with deletion requests. Such a provision would likely be unacceptable and could create liability. The policy should limit the provider's use and retention of data to what is necessary to deliver the service.
- ✗
A right for the provider to retain data beyond the agreed retention period if it is technically difficult to delete
Why it's wrong here
Technical difficulty is not a valid legal basis for retaining data beyond the agreed period. Regulations require deletion when the purpose for processing ends, regardless of technical challenges. Allowing indefinite retention due to technical difficulty would violate the policy's intent and could lead to non-compliance. Providers are expected to design systems that can honor deletion commitments.
- ✓
A process for the customer to request early deletion of specific data during the contract term and for the provider to confirm deletion
Why this is correct
Customers often need to delete specific data before contract end, such as when a data subject exercises the right to erasure or when data is no longer needed. A defined process with confirmation ensures the provider acts on these requests and provides auditability. This supports compliance with GDPR and other privacy laws that require timely deletion. It also helps manage storage costs and reduce risk.
- ✗
A clause stating that the provider may use customer data for marketing purposes after anonymization without customer consent
Why it's wrong here
Even anonymized data use should be governed by the contract, and using customer data for marketing without consent may violate privacy laws and contractual confidentiality. Anonymization must be robust to be outside GDPR scope, and the customer should approve such use. This clause does not belong in a retention and deletion policy, which focuses on limiting retention and ensuring deletion.
- ✓
A requirement that the provider delete all customer data within a specified period after contract termination, including from backups, and provide a certificate of destruction
Why this is correct
This is a critical contractual clause. It ensures that data is not retained indefinitely and that deletion extends to backups, which are often overlooked. A certificate of destruction provides evidence for audits and regulatory compliance. Without this, data could remain in the provider's environment, creating legal and security risks. This element directly addresses the customer's obligation to enforce retention limits.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.